目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-835 不可达退出条件的循环(无限循环) 类漏洞列表 334

CWE-835 不可达退出条件的循环(无限循环) 类弱点 334 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-835属于逻辑缺陷类漏洞,指程序包含无法到达退出条件的循环,导致无限执行。攻击者通常利用此缺陷发起拒绝服务攻击,通过触发无限循环耗尽服务器CPU资源或内存,使合法用户无法访问服务。开发者应避免此类问题,需确保循环变量在每次迭代中正确更新,并设置合理的边界检查或超时机制,保证循环最终能正常终止。

MITRE CWE 官方描述
CWE:CWE-835 具有不可达退出条件的循环('Infinite Loop') 英文:该产品包含一个迭代或循环,其退出条件无法被到达,即无限循环。
常见影响 (1)
Availability DoS: Resource Consumption (CPU), DoS: Resource Consumption (Memory), DoS: Amplification
An infinite loop will cause unexpected consumption of resources, such as CPU cycles or memory. The software's operation may slow down, or cause a long time to respond.
代码示例 (2)
In the following code the method processMessagesFromServer attempts to establish a connection to a server and read and process messages from the server. The method uses a do/while loop to continue trying to establish the connection to the server when an attempt fails.
int processMessagesFromServer(char *hostaddr, int port) { ... int servsock; int connected; struct sockaddr_in servaddr; // create socket to connect to server servsock = socket( AF_INET, SOCK_STREAM, 0); memset( &servaddr, 0, sizeof(servaddr)); servaddr.sin_family = AF_INET; servaddr.sin_port = htons(port); servaddr.sin_addr.s_addr = inet_addr(hostaddr); do { // establish connection to server connected = connect(servsock, (struct sockaddr *)&servaddr, sizeof(servaddr)); // if connected then read and process messages from server if (connected > -1) { // read and process messages ... } // keep tr
Bad · C
int processMessagesFromServer(char *hostaddr, int port) { ... // initialize number of attempts counter int count = 0; do { // establish connection to server connected = connect(servsock, (struct sockaddr *)&servaddr, sizeof(servaddr)); // increment counter count++; // if connected then read and process messages from server if (connected > -1) { // read and process messages ... } // keep trying to establish connection to the server // up to a maximum number of attempts } while (connected < 0 && count < MAX_ATTEMPTS); // close socket and return success or failure ... }
Good · C
For this example, the method isReorderNeeded is part of a bookstore application that determines if a particular book needs to be reordered based on the current inventory count and the rate at which the book is being sold.
public boolean isReorderNeeded(String bookISBN, int rateSold) { boolean isReorder = false; int minimumCount = 10; int days = 0; // get inventory count for book int inventoryCount = inventory.getIventoryCount(bookISBN); // find number of days until inventory count reaches minimum while (inventoryCount > minimumCount) { inventoryCount = inventoryCount - rateSold; days++; } // if number of days within reorder timeframe // set reorder return boolean to true if (days > 0 && days < 5) { isReorder = true; } return isReorder; }
Bad · Java
public boolean isReorderNeeded(String bookISBN, int rateSold) { ... // validate rateSold variable if (rateSold < 1) { return isReorder; } ... }
Good · Java
CVE ID 标题 CVSS 风险等级 Published
CVE-2023-25824 Mod_gnutls 安全漏洞 — mod_gnutls 7.5 High 2023-02-23
CVE-2023-25653 jose 安全漏洞 — node-jose 7.5 High 2023-02-16
CVE-2022-25734 Qualcomm 芯片安全漏洞 — Snapdragon 7.5 High 2023-02-09
CVE-2023-24808 PDFio 安全漏洞 — pdfio 5.3 Medium 2023-02-07
CVE-2022-46285 libXpm 安全漏洞 — libXpm 7.5 - 2023-02-07
CVE-2023-23617 OpenMage Magento Lts 安全漏洞 — magento-lts 4.9 Medium 2023-01-27
CVE-2021-33642 byacc 安全漏洞 — byacc 6.5 - 2023-01-20
CVE-2023-20020 Cisco BroadWorks Application 输入验证错误漏洞 — Cisco BroadWorks 8.6 High 2023-01-19
CVE-2022-39052 OTRS 安全漏洞 — OTRS 7.5 High 2022-10-17
CVE-2020-14394 QEMU 安全漏洞 — QEMU 6.0 - 2022-08-17
CVE-2022-34661 Siemens Teamcenter 命令注入漏洞 — Teamcenter V12.4 9.1 - 2022-08-10
CVE-2022-34862 F5 BIG-IP 安全漏洞 — BIG-IP 7.5 High 2022-08-04
CVE-2022-34760 多款Schneider Electric产品安全漏洞 — OPC UA Modicon Communication Module 7.5 High 2022-07-13
CVE-2022-29190 Pion DTLS 安全漏洞 — dtls 7.5 High 2022-05-20
CVE-2022-29028 Siemens JT2GO和Siemens Teamcenter Visualization 安全漏洞 — JT2Go 5.5 - 2022-05-10
CVE-2022-24792 PJSIP 安全漏洞 — pjproject 7.5 High 2022-04-25
CVE-2022-24859 PyPDF2 安全漏洞 — PyPDF2 6.2 Medium 2022-04-18
CVE-2022-21159 Mz Automation Libiec61850 安全漏洞 — libiec61850 7.5 - 2022-04-15
CVE-2022-1222 GPAC 安全漏洞 — gpac/gpac 5.5 - 2022-04-04
CVE-2022-24763 PJSIP 安全漏洞 — pjproject 7.5 High 2022-03-30
CVE-2021-20257 QEMU 安全漏洞 — QEMU 6.5 - 2022-03-16
CVE-2021-3737 SUSE Linux Enterprise Server 代码问题漏洞 — python 7.5 - 2022-03-04
CVE-2022-0711 Haproxy HAProxy 安全漏洞 — haproxy 7.5 - 2022-03-02
CVE-2022-23641 Discourse 安全漏洞 — discourse 6.5 Medium 2022-02-15
CVE-2021-20041 SonicWall SMA100安全漏洞 — SonicWall SMA100 7.5 - 2021-12-08
CVE-2021-41973 Apache MINA 安全漏洞 — Apache MINA 6.5 - 2021-11-01
CVE-2021-31363 Juniper Networks Junos OS 安全漏洞 — Junos OS 6.5 Medium 2021-10-19
CVE-2021-39194 charleskorn kaml 安全漏洞 — kaml 4.3 Medium 2021-09-07
CVE-2021-37714 Github jsoup 安全漏洞 — jsoup 7.5 High 2021-08-18
CVE-2021-37686 Google TensorFlow 安全漏洞 — tensorflow 5.5 Medium 2021-08-12

CWE-835(不可达退出条件的循环(无限循环)) 是常见的弱点类别,本平台收录该类弱点关联的 334 条 CVE 漏洞。